A compliance filter rule can cause a malicious email to be delivered. This is not a malfunction but rather an insufficiently configured, self-created rule.
How to recognize that a compliance filter rule has taken effect:
Go to the small gear icon on the right side to access additional column selections. There you can select the column "Reason." You can find a detailed article about this here: Customizing the display in Email Live Tracking.
You also have the option to view the reason via the email details of the email. More information can be found here: Advanced Email Information.
If the email was marked as "Valid" due to a compliance filter, you will see the following indicated as the "Reason": clean by compliance rule id=xxxxxxx
Using the "rule id" you can identify the exact compliance filter rule that caused the email to be declared valid. If you want to block the delivery, you can view and deactivate the compliance filter rule. Search for the corresponding compliance filter ID in the appropriate module. For more information, please see the following article in our manual: Deactivate compliance filter rule